Subscribe to the Non-Human & AI Identity Journal
Home FAQ Cyber Security Why do business email compromise attacks often bypass…
Cyber Security

Why do business email compromise attacks often bypass technical email filters?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 2, 2026 Domain: Cyber Security

Because the attacker may use a real account, a valid token, or a lookalike business process rather than a simple spoof. Email security can reduce obvious impersonation, but it cannot judge whether a payment request fits normal approval logic. That is why BEC defence must combine authentication, identity monitoring, and finance workflow checks.

Why This Matters for Security Teams

business email compromise succeeds because it targets trust, not just transport. Mail gateways can spot many forged headers, obvious phishing domains, and known malicious links, but they are much less effective when an attacker uses a compromised mailbox, a legitimate cloud account, or a message that fits a real business relationship. That creates a control gap between email authenticity and business legitimacy. Guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant here because the problem spans identity, monitoring, and process controls rather than a single email filter setting.

Security teams often overestimate the value of blocking malicious content and underestimate the value of detecting abnormal sender behaviour, impossible travel, token misuse, and changes in payment workflows. BEC also bypasses controls because the message content is often low-noise and business-like, making it hard to flag without context from identity systems, finance approvals, and user behaviour analytics. In practice, many security teams encounter BEC only after a wire transfer, payroll diversion, or vendor banking change has already been approved through a normal-looking process, rather than through intentional prevention.

How It Works in Practice

Effective BEC defence treats email as one signal inside a broader trust chain. The first layer is technical identity protection: phishing-resistant authentication, conditional access, mailbox auditing, and alerting on risky sign-ins or forwarding-rule changes. The second layer is business process control: dual approval for payments, independent verification for bank-detail changes, and out-of-band callbacks for urgent requests. The third layer is detection and response, where SOC teams correlate mailbox activity, identity logs, and finance exceptions to catch abuse quickly.

Attackers often exploit one of four patterns: credential theft, session token theft, abuse of an existing trusted mailbox, or impersonation of a senior executive or supplier. Once inside, they may create inbox rules, forward messages externally, or wait for a payment cycle and then insert a convincing request. The MITRE ATT&CK Enterprise Matrix is useful for mapping these behaviours to techniques such as valid account abuse and email collection, while MITRE ATT&CK Enterprise Matrix helps teams translate a “why did the filter miss this?” question into concrete detection coverage.

  • Monitor for mailbox rule creation, unusual OAuth consent, and suspicious token reuse.
  • Require verified approval paths for supplier changes and urgent payment requests.
  • Correlate identity risk, device posture, and message context before trusting high-impact requests.
  • Use SIEM and SOAR playbooks to freeze payments and notify finance when suspicious activity appears.

CISA guidance is useful for prioritising the most common business email compromise behaviours and mapping them to response steps, especially when incidents move from mailbox abuse to financial fraud. These controls tend to break down when finance exceptions are frequent, approval ownership is unclear, or legacy mail systems cannot surface identity telemetry because the process layer becomes the attacker’s easiest path.

Common Variations and Edge Cases

Tighter controls often increase friction for executives, finance teams, and vendors, requiring organisations to balance speed against verification. That tradeoff is real, because overly rigid approval flows can delay legitimate transactions, while loose controls create a path for social engineering and account takeover. Best practice is evolving, but there is no universal standard for how much out-of-band verification is enough across all businesses.

Some BEC cases do not involve malware or obvious phishing at all. A compromised supplier mailbox may send routine invoice updates for weeks before a fraudulent bank-detail change is requested. In other cases, attackers use a real executive account, making content filters effectively blind. This is where identity governance matters: mailbox access, privileged role assignment, and session controls should be reviewed alongside finance process exceptions. Where AI-assisted impersonation is involved, the line between phishing and synthetic social engineering becomes harder to see, so current guidance suggests combining human verification with anomaly detection rather than relying on message inspection alone. For AI-driven phishing and impersonation trends, Anthropic — first AI-orchestrated cyber espionage campaign report and MITRE ATLAS adversarial AI threat matrix are helpful references, though the exact mix of controls should reflect the organisation’s tooling and fraud exposure.

Where payments are low-volume but high-value, or where outsourced finance processes rely on email as the primary approval channel, the standard “filter plus awareness training” answer breaks down quickly.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.ACIdentity and access controls are central when BEC uses real accounts or stolen sessions.
NIST AI RMFAI risk guidance helps when synthetic impersonation or AI-assisted phishing is part of BEC.
MITRE ATT&CKT1078Valid Accounts is a common BEC path when attackers use compromised mailboxes.
NIST SP 800-53 Rev 5AU-2Audit logging is needed to reconstruct mailbox abuse and suspicious workflow changes.

Harden identity verification, access reviews, and session controls around all high-risk mail and finance workflows.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org